mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-09-13 05:47:23 -04:00
* fix(tests): resolve all phpunit failures (#4626) Bring the phpunit suite from 153 failures to 0 (281 tests passing): - Employee: decouple grants block from save_value success; restructure save_employee new-employee + disallowed-grants early return - Sale: unify sales_payments_temp schema (add sale_cash_refund, reference_code) so both creators produce an identical superset table - Employees controller: provide placeholder password/hash in testing env so new-employee insert succeeds and grant logic is testable - TestDatabaseBootstrapSeeder: reset shared connection table-name cache after bootstrap reset to avoid stale listTables()/tableExists() results - Config: fix postSaveLocale validation rule syntax - Test data: use unique employee usernames to avoid UNIQUE constraint collisions latching strict-mode transStatus=false on the shared conn - Various test-file and language-string corrections * test: consolidate employee fixtures in shared trait Route test employee creation through a single EmployeeFixtureTrait that delegates to Employee::save_employee(), so fixtures exercise the same production code path instead of raw DB inserts. Removes six near-duplicate helpers across EmployeeTest, SalesControllerTest, and EmployeesControllerTest while preserving each test's specific grant set. Closes a piece of the fixture-scattering flagged in #4626. Closes #4626 * test: add global DROP/CREATE grant and commit theme fixtures * fix(ci): remove redundant symlink step, set working encryption key * fix(ci): run phpunit with --no-coverage to avoid no-driver warning * fix: address code review findings - Config: restore strict locale validation (min required|integer|>0) and fix max cross-field check with a new gte_field rule (CI4's greater_than_equal_to[field] does not resolve the field value) - Tests: assert rejection for non-numeric/zero/negative/min>max limits - .env.example: remove shared hard-coded encryption.key (auto-generates); document Docker env-var usage - phpunit.yml: scope CREATE/DROP grant to ospos_test.* and provision a per-run encryption key as an env var * feat: support ENCRYPTION_KEY env var for encryption key Read ENCRYPTION_KEY as a fallback for the encryption key when the config value is empty. This is a supported, reliable path for Docker / container deploys and CI, avoiding reliance on the raw dotted encryption.key env var. * fix: align Summary_report temp tables with Sale temp table schema Summary_report created sales_items_taxes_temp and sales_payments_temp with fewer columns than the canonical create_temp_table() in Sale.php. A later reader expecting those columns hit a schema-mismatch SQL error on the shared temp tables. Add internal_tax/sales_tax (sales_items_taxes_temp) and reference_code (sales_payments_temp) so all creators emit the identical column set.
120 lines
3.7 KiB
PHP
120 lines
3.7 KiB
PHP
<?php
|
|
|
|
namespace Config;
|
|
|
|
use CodeIgniter\Config\BaseConfig;
|
|
|
|
/**
|
|
* Encryption configuration.
|
|
*
|
|
* These are the settings used for encryption, if you don't pass a parameter
|
|
* array to the encrypter for creation/initialization.
|
|
*/
|
|
class Encryption extends BaseConfig
|
|
{
|
|
/**
|
|
* --------------------------------------------------------------------------
|
|
* Encryption Key Starter
|
|
* --------------------------------------------------------------------------
|
|
*
|
|
* If you use the Encryption class you must set an encryption key (seed).
|
|
* You need to ensure it is long enough for the cipher and mode you plan to use.
|
|
* See the user guide for more info.
|
|
*/
|
|
public string $key = '';
|
|
|
|
/**
|
|
* --------------------------------------------------------------------------
|
|
* Previous Encryption Keys
|
|
* --------------------------------------------------------------------------
|
|
*
|
|
* When rotating encryption keys, add old keys here to maintain ability
|
|
* to decrypt data encrypted with previous keys. Encryption always uses
|
|
* the current $key. Decryption tries current key first, then falls back
|
|
* to previous keys if decryption fails.
|
|
*
|
|
* In .env file, use comma-separated string:
|
|
* encryption.previousKeys = hex2bin:9be8c64fcea509867...,hex2bin:3f5a1d8e9c2b7a4f6...
|
|
*
|
|
* @var list<string>|string
|
|
*/
|
|
public array|string $previousKeys = '';
|
|
|
|
/**
|
|
* --------------------------------------------------------------------------
|
|
* Encryption Driver to Use
|
|
* --------------------------------------------------------------------------
|
|
*
|
|
* One of the supported encryption drivers.
|
|
*
|
|
* Available drivers:
|
|
* - OpenSSL
|
|
* - Sodium
|
|
*/
|
|
public string $driver = 'OpenSSL';
|
|
|
|
/**
|
|
* --------------------------------------------------------------------------
|
|
* SodiumHandler's Padding Length in Bytes
|
|
* --------------------------------------------------------------------------
|
|
*
|
|
* This is the number of bytes that will be padded to the plaintext message
|
|
* before it is encrypted. This value should be greater than zero.
|
|
*
|
|
* See the user guide for more information on padding.
|
|
*/
|
|
public int $blockSize = 16;
|
|
|
|
/**
|
|
* --------------------------------------------------------------------------
|
|
* Encryption digest
|
|
* --------------------------------------------------------------------------
|
|
*
|
|
* HMAC digest to use, e.g. 'SHA512' or 'SHA256'. Default value is 'SHA512'.
|
|
*/
|
|
public string $digest = 'SHA512';
|
|
|
|
/**
|
|
* Whether the cipher-text should be raw. If set to false, then it will be base64 encoded.
|
|
* This setting is only used by OpenSSLHandler.
|
|
*
|
|
* Set to false for CI3 Encryption compatibility.
|
|
*/
|
|
public bool $rawData = false;
|
|
|
|
/**
|
|
* Encryption key info.
|
|
* This setting is only used by OpenSSLHandler.
|
|
*
|
|
* Set to 'encryption' for CI3 Encryption compatibility.
|
|
*/
|
|
public string $encryptKeyInfo = '';
|
|
|
|
/**
|
|
* Authentication key info.
|
|
* This setting is only used by OpenSSLHandler.
|
|
*
|
|
* Set to 'authentication' for CI3 Encryption compatibility.
|
|
*/
|
|
public string $authKeyInfo = '';
|
|
|
|
/**
|
|
* Cipher to use.
|
|
* This setting is only used by OpenSSLHandler.
|
|
*
|
|
* Set to 'AES-128-CBC' to decrypt encrypted data that encrypted
|
|
* by CI3 Encryption default configuration.
|
|
*/
|
|
public string $cipher = 'AES-256-CTR';
|
|
|
|
public function __construct()
|
|
{
|
|
parent::__construct();
|
|
|
|
if ($this->key === '') {
|
|
$envKey = getenv('ENCRYPTION_KEY');
|
|
$this->key = $envKey === false ? '' : $envKey;
|
|
}
|
|
}
|
|
}
|